Cookie Consent by Free Privacy Policy Generator 📌 Prison Phone Company Leaked 600,000 Users' Data and Didn't Notify Them

🏠 Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeiträge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden Überblick über die wichtigsten Aspekte der IT-Sicherheit in einer sich ständig verändernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch übersetzen, erst Englisch auswählen dann wieder Deutsch!

Google Android Playstore Download Button für Team IT Security



📚 Prison Phone Company Leaked 600,000 Users' Data and Didn't Notify Them


💡 Newskategorie: IT Security Nachrichten
🔗 Quelle: yro.slashdot.org

An anonymous reader quotes a report from Ars Technica: Prison phone company Global Tel*Link leaked the personal information of nearly 650,000 users and failed to notify most of the users that their personal data was exposed, the Federal Trade Commission said today. The company agreed to a settlement that requires it to change its security practices and offer free credit monitoring and identity protection to affected users, but the settlement doesn't include a fine. "Global Tel*Link and two of its subsidiaries failed to implement adequate security safeguards to protect personal information they collect from users of its services, which enabled bad actors to gain access to unencrypted personal information stored in the cloud and used for testing," the FTC said. A security researcher notified Global Tel*Link of the breach on August 13, 2020, according to the FTC's complaint (PDF). This happened just after "the company and a third-party vendor copied a large volume of sensitive, unencrypted personal information about nearly 650,000 real users of its products and services into the cloud but failed to take adequate steps to protect the data," the FTC said. The data was copied to an Amazon Web Services test environment to test a new version of a search software product. For about two days, the data was in the test environment and "accessible via the Internet without password protection or other access controls," the FTC said. After hearing from the security researcher, Global Tel*Link reconfigured the test environment to cut off public access. But a few weeks later, the firm was notified by an identity monitoring vendor that the data was available on the dark web. Global Tel*Link didn't notify any users until May 2021, and even then, it only notified a subset of them, according to the FTC. [...] The complaint said that Global Tel*Link violated the Federal Trade Commission Act's section on unfair or deceptive acts or practices and charged the firm with unfair data security practices, unfair failure to notify affected consumers of the incident, misrepresentations regarding data security, misrepresentations to individual users regarding the incident, misrepresentations to individual users regarding notice, and deceptive representations to prison facilities regarding the incident. To settle the charges, the company agreed to new security protocols, including "'change management' measures to all of its systems to help reduce the risk of human error, use of multifactor authentication, and procedures to minimize the amount of data it collects and stores," the FTC said. Global Tel*Link also has to notify the affected users who were not previously notified of the breach and provide them with credit monitoring and identity protection products. The product must include $1,000,000 worth of identity theft insurance to cover costs related to identity theft or fraud. The company must also notify consumers and prison facilities within 30 days of future data breaches and notify the FTC of the incidents, the agency said. Violations of the settlement could result in fines of $50,120 for each violation, the FTC said.

Read more of this story at Slashdot.

...



📌 Prison Phone Company Leaked 600,000 Users' Data and Didn't Notify Them


📈 99.06 Punkte

📌 AI’s Secret Future Blueprint LEAKED: How Brain Power Is The $25,000,000,000,000 Answer ...


📈 28.32 Punkte

📌 Didn’t set root password and I can’t get pass this screen. I tried to use my usb with the iso but it didn’t load. Arch


📈 28.11 Punkte

📌 Facebook Does Not Plan To Notify Half-Billion Users Affected by Data Leak


📈 26.46 Punkte

📌 Shein Owner Fined $1.9 Million For Failing To Notify 39 Million Users of Data Breach


📈 26.46 Punkte

📌 Clerk Printed Lottery Tickets She Didn't Pay For But Didn't Break Hacking Law


📈 26.33 Punkte

📌 Hawaii Governor Didn't Correct False Missile Alert Sooner Because He Didn't Know His Twitter Password


📈 26.33 Punkte

📌 Clerk Printed Lottery Tickets She Didn't Pay For But Didn't Break Hacking Law


📈 26.33 Punkte

📌 Data of 200,000 people who write fake reviews in Amazon leaked. Legal action will be taken against them


📈 25.77 Punkte

📌 533 Million Facebook Users' Phone Numbers and Personal Data Leaked Online


📈 25.04 Punkte

📌 533 Million Facebook Users' Phone Numbers And Personal Data Leaked Online


📈 25.04 Punkte

📌 533 Million Facebook Users’ Phone Numbers and Personal Data Leaked Online


📈 25.04 Punkte

📌 Prison Inmates Built PCs from e-Waste and Connected Online Using Prison Network


📈 24.69 Punkte

📌 US actor casting company leaked private data of over 260,000 individuals


📈 24.65 Punkte

📌 Wrote malware for money, went straight, got busted, didn’t go to prison. has us cybercrime enforcement gone soft?


📈 24.62 Punkte

📌 SAP to Address Security Issues With Some Cloud Products and to Notify 440,000 Customers


📈 24.55 Punkte

📌 CVE-2023-20079 | Cisco IP Phone 6800/IP Phone 7800/IP Phone 8800 denial of service (cisco-sa-ip-phone-cmd-inj-KMFynVcP)


📈 24.15 Punkte

📌 CVE-2023-20078 | Cisco IP Phone 6800/IP Phone 7800/IP Phone 8800 command injection (cisco-sa-ip-phone-cmd-inj-KMFynVcP)


📈 24.15 Punkte

📌 Your Android phone can notify you of an earthquake seconds before it happens. Here's how


📈 23.88 Punkte

📌 Prison phone service can expose the location of anyone with a phone


📈 23.53 Punkte

📌 Email provider got hacked, data of 600,000 users now sold on the dark web


📈 23.52 Punkte

📌 Email.it Data Breach Exposes 600,000 Users – Expert Commentary


📈 23.52 Punkte

📌 Over 600,000 stolen credit cards leaked after Swarmshop hack


📈 23.52 Punkte











matomo